Project

General

Profile

Actions

Feature #341

closed

urilen option to match on raw uri

Added by Victor Julien over 12 years ago. Updated over 12 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

By default Suricata's urilen matches on the normalized buffer. Snort 2.9.1 added support for matching on both the raw and normalized buffers:

urilen:min<>max[,<uribuf>];
urilen:[<|>]<number>[,<uribuf>];
<uribuf> : "norm" | "raw" 

It seems that Snort selects the raw uri by default.


Files

Actions #1

Updated by Victor Julien over 12 years ago

  • Assignee changed from OISF Dev to Anoop Saldanha
  • Target version changed from 1.2beta1 to 1.2rc1
  • Estimated time set to 5.00 h
Actions #3

Updated by Victor Julien over 12 years ago

  • Status changed from New to Closed
  • % Done changed from 0 to 100

Applied, thanks Anoop!

Actions

Also available in: Atom PDF